Job Openings Data Protection Officer

About the job Data Protection Officer

Mission Overview:


We are seeking a Data Protection Officer (DPO) for a consultancy mission at a client site, representing Keystone Solutions. The DPO will play a critical role in ensuring compliance with GDPR regulations within a federal government agency. This position requires a self-sufficient individual who will report directly to the management team.


Key Responsibilities:


The DPO will carry out the following responsibilities under Keystone Solutions' consultancy model:

  • Oversee compliance with GDPR, privacy legislation, and relevant regulations.
  • Advise management and services on their data protection obligations.
  • Contribute to the development, documentation, and follow-up of a coherent framework of roles, responsibilities, procedures, and reporting mechanisms regarding data protection.
  • Report to senior management on the status, risks, and improvements regarding data protection.
  • Ensure the independence of the DPO function and avoid conflicts of interest.

Data Processing Activities:


  • Oversee the creation, maintenance, and updating of the register of processing activities.
  • Support internal services in identifying and documenting personal data processing.
  • Evaluate processing purposes, legal grounds, retention periods, and data flows.

Data Protection Impact Assessments (DPIA):


  • Advise on the necessity of conducting DPIAs.
  • Guide and assess DPIAs for new or modified processing activities.
  • Monitor mitigating measures and follow up on residual risks.
  • Advise on prior consultation with the Data Protection Authority if required.

Policy Role & Strategic Advice:


  • Contribute to the development, evaluation, and updating of the data protection policy.
  • Advise on strategic choices, new initiatives, and digitalization projects from a data protection perspective.
  • Integrate data protection into broader governance, compliance, and risk management frameworks.
  • Identify structural issues and formulate policy recommendations to management.
  • Formulate policy recommendations regarding personal data protection and coordinate the drafting and implementation of policy plans, guidelines, procedures, and control measures based on legislation, case law, and legal doctrine.

Data Breaches & Incidents:


  • Advise on the assessment and handling of personal data breaches.
  • Ensure compliance with legal notification obligations, including reporting to the Data Protection Authority within the required timeframe.
  • Advise on and follow up on notifications to affected individuals if required.
  • Support the organization in establishing a mechanism for timely assessment and reporting of data breaches.
  • Evaluate the causes of data breaches and formulate recommendations for corrective and preventive measures.

Contracts & Processors:


  • Advise on processor agreements and data protection clauses.
  • Ensure compliance with GDPR requirements by processors and partners.
  • Identify privacy risks in outsourcing and collaboration agreements.
  • Act as a contact point for the Data Protection Authority.
  • Collaborate with other supervisory authorities as relevant.
  • Participate in the information security committee.

Awareness & Training:


  • Develop and support awareness and training initiatives regarding data protection.
  • Act as a point of contact for employees regarding personal data inquiries.
  • Contribute to a privacy-conscious organizational culture.

Must Have:


  • Proven knowledge of GDPR and data protection principles.
  • At least 8 years of experience in data protection.
  • Experience with risk analysis methodologies.
  • Technical knowledge of secure data exchange between government organizations.
  • Experience in developing and implementing policies and procedures for data protection.

Nice to Have:


  • Knowledge of NIS2, Cyfun.
  • Experience working in a government agency.

Behavioral Competencies:


  • Communication and Collaboration.
  • Integrity in handling sensitive information.
  • Ability to work independently and make decisions.
  • Analytical skills to identify risks quickly.
  • Proactive and decisive in problem-solving.
  • Ability to make complex regulations accessible to non-legal audiences.

Language Skills:


The DPO must be fluent in either Dutch or French and have a good understanding of the other language.


If you are ready to tackle technical and strategic challenges in a dynamic consultancy environment, apply today at Keystone Solutions Career Portal.


Duration: As soon as possible - 31/12/2026 4 months • (full time)


Skills required:

  • Aansturen van beleid, procedures en richtsnoeren inzake de bescherming van persoonsgegevens - Level: Confirmed - Most recent: Any time
  • Ervaring in persoonsgegevensbescherming - Level: Confirmed - Most recent: Any time
  • Ervaring met risicoanalyse-methodieken (zoals DPIA-modellen) - Level: Confirmed - Most recent: Any time
  • Kennis van de GDPR, persoonsgegevensbeschermingsprincipes en aanverwante wetgeving - Level: Confirmed - Most recent: Any time
  • Technische kennis van beveiligde data-uitwisseling tussen overheidsorganisaties - Level: Junior - Most recent: Any time

Language requirements:

Dutch
Level Native
English
Level Active knowledge
French
Level Native